Loading HuntDB...

GHSA-4f8g-fq6x-jqrr

GitHub Security Advisory

org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact

Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view rights provided on a space of a deleted document are properly checked.

### Patches

The problem has been patched in XWiki 14.10 by checking the rights of current user: only admin and deleter of the document are allowed to view it.

### Workarounds

There is no workaround for this vulnerability other than upgrading.

### References

* Jira ticket: https://jira.xwiki.org/browse/XWIKI-16285
* Commit: https://github.com/xwiki/xwiki-platform/commit/d9e947559077e947315bf700c5703dfc7dd8a8d7

### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Jira](https://jira.xwiki.org)
* Email us at [security ML](mailto:[email protected])

Affected Packages

Maven org.xwiki.platform:xwiki-platform-oldcore
Affected versions: 1.2-milestone-1 (fixed in 13.10.11)
Maven org.xwiki.platform:xwiki-platform-oldcore
Affected versions: 14.0-rc-1 (fixed in 14.4.7)
Maven org.xwiki.platform:xwiki-platform-oldcore
Affected versions: 14.5 (fixed in 14.10)

Related CVEs

Key Information

GHSA ID
GHSA-4f8g-fq6x-jqrr
Published
April 12, 2023 8:34 PM
Last Modified
April 16, 2023 7:16 AM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.xwiki.platform:xwiki-platform-oldcore
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 22, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.